EventPrime – Events Calendar, Bookings and Tickets <= 4.3.0.0 - Authenticated (Subscriber+) Insecure Direct Object Reference
EventPrime – Events Calendar, Bookings and Tickets
Minimum safe version
4.3.0.1
Update to 4.3.0.1 or later to address 44 fixable vulnerabilities
EventPrime <= 4.2.8.4 - Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint
EventPrime <= 4.2.8.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Event Modification via 'event_id' Parameter
CVE-2026-24378
CVE-2025-69358
CVE-2026-25312
EventPrime <= 4.2.8.3 - Unauthenticated Information Exposure
EventPrime <= 4.2.8.0 - Missing Authorization
CVE-2025-14507
CVE-2025-63007
CVE-2025-63006
CVE-2025-12498
EventPrime – Events Calendar, Bookings and Tickets <= 3.5.0 - Insecure Direct Object Reference to (Subscriber+) Arbitrary Booking Update
CVE-2024-13526
CVE-2024-12024
CVE-2024-9864
CVE-2024-9865
CVE-2024-47648
CVE-2024-8369
CVE-2024-43223
EventPrime – Modern Events Calendar, Bookings and Tickets < 3.3.3 - Contributor+ Stored XSS
CVE-2024-31275
CVE-2024-29776
CVE-2024-1124
CVE-2024-1321
CVE-2024-1320
CVE-2024-1123
CVE-2024-1125
CVE-2024-1127
CVE-2024-1126
CVE-2024-24832
WordPress EventPrime Plugin <= 3.3.9 is vulnerable to Broken Access Control
CVE-2023-6447
CVE-2023-4252
WordPress EventPrime Plugin <= 3.3.2 is vulnerable to Cross Site Scripting (XSS)
EventPrime – Modern Events Calendar, Bookings and Tickets <= 3.3.2 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
CVE-2023-5238
CVE-2023-5519
CVE-2023-4251
CVE-2023-4250
CVE-2023-45637
CVE-2023-35884
CVE-2023-33321
CVE-2023-33326